<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="margin:0px;font-size:12pt;background-color:rgb(255, 255, 255)"><span style="margin:0px;font-size:14.67px">Hello,</span></span>
<div style="margin:0px;font-size:15px;font-family:"Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif;color:rgb(32, 31, 30);background-color:rgb(255, 255, 255)">
<div style="margin:0px;font-size:12pt;font-family:Calibri, Arial, Helvetica, sans-serif;color:rgb(0, 0, 0)">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30);background-color:rgb(255, 255, 255)">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0)">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px">
<div style="margin:0px;background-color:rgb(255, 255, 255)">
<div style="margin:0px;color:rgb(0, 0, 0) !important;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:14.67px;background-color:white !important">I hope everyone is doing well!</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important">Below is the entry for today.</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important">12/03/2021 - Diary entry #404<br>
<br>
</div>
<blockquote style="font-size:14.67px;margin-top:0px;margin-bottom:0px;background-color:white !important">
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
In our Daily Diary #390 we covered emotet's return, with a new campaign using Trickbot to deploy the malware payload.
<div><br>
</div>
<div>Now a new campaign has been found using the Windows 10 App Installer to deploy the payload, in the 'call me back' attack covered in our Daily Diary #388. In this attack users are targeted with spam messages containing a link to a phishing URL. The malicious
 page mimics a PDF loading error, asking the user to install Adobe Reader to access it. The Windows 10 App Installer then opens a pop-up, asking for the installation of the payload disguised as AdobePDF component. Using this technique is very effective. As
 the Windows 10 App Installer itself is trusted, users unaware of the scam will easily allow the malware installation.</div>
<div><br>
</div>
It's still not clear if this new Emotet's version is developed by the same threat actors, but the change in the M.O. suggests that a new group is using Emotet to grow its own operation (possibly along with older members of the original Emotet's operation).<span style="margin:0px"></span>
<div style="margin:0px"></div>
<div style="margin:0px"><br>
</div>
<div style="margin:0px"></div>
</blockquote>
<span style="margin:0px;font-size:14.67px;background-color:white !important">Kind Regards,</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div></div>
<div></div>
<div></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table style="font-family:"Times New Roman"; font-size:medium; text-align:start">
<tbody>
<tr>
<td width="180" align="left" style="width:180px">
<table width="120" align="left">
<tbody>
<tr>
<td colspan="3" align="center"><a href="https://www.appgate.com/"><img alt="" width="120" height="30" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/logo@2x.png"></a></td>
</tr>
<tr>
<td colspan="3" align="center"> </td>
</tr>
<tr>
<td width="37%" align="center"><a href="https://www.linkedin.com/company/appgate-security/"><img width="18" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/likedin@2x.png"></a></td>
<td width="28%"><a href="https://twitter.com/AppgateSecurity"><img width="20" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/twitter@2x.png"></a></td>
<td width="35%"><a href="https://www.youtube.com/channel/UC-8GvxcZbm-R3EJNl8jYjiQ"><img width="26" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/youtube@2x.png"></a></td>
</tr>
</tbody>
</table>
<p> </p>
</td>
<td width="350" colspan="2" rowspan="2" style="width:350px">
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
<strong>Felipe Duarte Domingues</strong><br>
Security Researcher<br>
<strong>Appgate</strong></p>
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
E:<span> </span><font color="#228ebe"><a href="mailto:felipe.duarte@appgate.com" title="mailto:felipe.duarte@appgate.com">felipe.duarte@appgate.com</a></font><br>
O: <span style="background-color:rgb(255,255,255); display:inline!important">+55 19 98840 2509</span></p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
</div>
</div>
</div>
</body>
</html>